Skip to main content

phpMyAdmin HTTP Response Splitting and File Inclusion Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 26 Mar 2009 4899 Views

RISK: Medium Risk

Two vulnerabilities have been identified in phpMyAdmin, which could be exploited by attackers to disclose sensitive information or bypass security restrictions. These issues are caused by input validation errors in the BLOB streaming feature, which could allow arbitrary file inclusion and HTTP header inject attacks.


Impact

  • Information Disclosure

System / Technologies affected

  • phpMyAdmin verisons prior to 3.1.3.1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link